Invention Application
US20170048265A1 Detection of Potential Security Threats Based on Categorical Patterns
审中-公开
基于分类模式检测潜在的安全威胁
- Patent Title: Detection of Potential Security Threats Based on Categorical Patterns
- Patent Title (中): 基于分类模式检测潜在的安全威胁
-
Application No.: US15339955Application Date: 2016-11-01
-
Publication No.: US20170048265A1Publication Date: 2017-02-16
- Inventor: Munawar Monzy Merza , John Coates , James M. Hansen , Lucas Murphey , David Hazekamp , Michael Kinsley , Alexander Raitz
- Applicant: Splunk Inc.
- Main IPC: H04L29/06
- IPC: H04L29/06

Abstract:
A metric value is determined for each event in a set of events that characterizes a computational communication or object. For example, a metric value could include a length of a URL or agent string in the event. A subset criterion is generated, such that metric values within the subset are relatively separated from a population's center (e.g., within a distribution tail). Application of the criterion to metric values produces a subset. A representation of the subset is presented in an interactive dashboard. The representation can include unique values in the subset and counts of corresponding event occurrences. Clients can select particular elements in the representation to cause more detail to be presented with respect to individual events corresponding to specific values in the subset. Thus, clients can use their knowledge system operations and observance of value frequencies and underlying events to identify anomalous metric values and potential security threats.
Public/Granted literature
- US10091227B2 Detection of potential security threats based on categorical patterns Public/Granted day:2018-10-02
Information query